{"id":"MAL-2026-15558","summary":"Malicious code in mfakit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f11dc9d39df6906a4b784b0cb3a584b5307816d20c4cc04fb28bbb40f59c3fb8)\nThe package advertises itself as a lightweight Discord MFA library, but require() of its main entry loads lib/cache.js which schedules a setImmediate handler that runs on Windows (guarded by process.env.SystemRoot). The handler XOR-decodes hidden hex constants against a base64 salt to reconstruct a fetch URL (https://limbomail.com/api/attachment/r_Ea6rT_kGfT.o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiw) and OS-command tokens (child_process, spawn, execSync, wscript.exe, node.exe, attrib +h +s). It downloads a script to %APPDATA%\\Microsoft\\Windows\\WinSxS\\Backup\\winsvc.js, hides it with attrib +h +s, spawns it detached under node.exe, writes a.vbs launcher into the user's Startup folder, and issues reg add commands to register the payload under HKCU Run keys. A timer re-fetches the payload every ~2 hours. None of this behavior is disclosed in package.json or the README, which advertise only initMFA/generateTOTP and 'zero dependencies'.\n","modified":"2026-08-29T02:30:12.888662833Z","published":"2026-08-29T02:08:33Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-29T02:08:33Z","sha256":"f11dc9d39df6906a4b784b0cb3a584b5307816d20c4cc04fb28bbb40f59c3fb8","source":"amazon-inspector","versions":["1.4.0"],"id":"IN-MAL-2026-019127","import_time":"2026-08-29T02:22:19.683304637Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/mfakit/v/1.4.0"}],"affected":[{"package":{"name":"mfakit","ecosystem":"npm","purl":"pkg:npm/mfakit"},"versions":["1.4.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"mfakit-1.4.0.tgz","hashes":{"sha512_sri":"sha512-aJY3ave1EMj1ZrkOoeD+/Fi3ACnONchj+WeAo2O/IBuGsBEIWGzXQa9VjRsxYdya+60ODXQqcMliVUHB0AASQg==","sha1":"5c054fba03f0516956f0a00fd595e922d9e878cf"}}],"evidence_files":[{"sha256":"29a0246e5a9f8b39d72ec1bf7d35ba169388a606aa0802c0aada70ec499934c3","tlsh":"d5d1d84b3ab11224569281ee9a4f813a726ad8513547d5e47b5c01ac3fd363cc6f38ed","path":"lib/cache.js"},{"tlsh":"0a51b91652f7783324a79182fe41bd91de219005930b4482199ee8cdb0cdae9cb7f5cf","path":"README.md","sha256":"5022df350572e179be8aa80150d992a11549b79c83c57bd9950442f54b73bd58"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfakit/MAL-2026-15558.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}